CVE-2026-81290
largeUnauthenticated XSS in WordPress Email Subscribers & Newsletters plugin
CVE-2026-81290 is an unauthenticated cross-site scripting (CWE-79) flaw in the Email Subscribers & Newsletters WordPress plugin, affecting all versions through 5.9.33. The CVSS vector (network attack vector, low complexity, no privileges required, changed scope, user interaction required) indicates an attacker can trigger script execution in the browser of a different user, such as a logged-in site administrator, without holding an account on the site. A successful attack lets the attacker run attacker-controlled JavaScript in the victim's browser, which can enable actions performed with that user's privileges (e.g., session hijacking or unauthorized admin actions), with confidentiality and integrity impact scored as limited. Any WordPress site running the plugin at version 5.9.33 or earlier is affected; the site's visitors and logged-in users are the exposed population. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns a 0.2% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known at this time.
What to do: Update Email Subscribers & Newsletters to the first release newer than 5.9.33 published by the vendor (check the plugin's changelog/security advisory for the exact fixed version). Verify the installed version in the WordPress admin Plugins list and patch promptly despite the low current exploitation risk, as unauthenticated XSS is trivially weaponized once a PoC appears. If immediate patching is not possible, monitor for public exploit releases and review the plugin's visitor-facing surfaces for unvalidated input.
| Icegram Email Subscribers & Newsletters (Icegram Express) WordPress plugin | <= 5.9.33 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.